09/28 2026
333
Recently, during the National Cybersecurity Promotion Week held in Jinan, the National Cybersecurity Standardization Committee officially unveiled the 'AI Security Governance Framework 3.0'.
This event signifies the third update to the framework within a span of three years. Initially, I harbored doubts about the necessity of updating a guiding document annually, considering it might be excessive.
However, a comprehensive review of the three versions reveals a different narrative: it's not that the document is update-happy; rather, AI has undergone such rapid transformations over these three years that regulations established the previous year are no longer adequate to govern the latest advancements.

A Three-Year Leap: Each Version Keeps Pace with AI's Evolution
To grasp the essence of Version 3.0, one must first understand the focus of its predecessors.
Version 1.0, released in 2024, concentrated on inherent and application security, aiming to prevent models from making autonomous errors and deter misuse by others. Version 2.0, in 2025, broadened its scope to include derivative risks, beginning to tackle AI's impact on employment and ethics, while proposing fundamental principles for trustworthy AI.
By Version 3.0, a qualitative shift has occurred. According to Associate Professor Wen Yuheng from China University of Political Science and Law, since late last year, large models have transcended mere question-answering capabilities; they now embody intelligent agents capable of proactively executing tasks. AI can now independently plan, invoke tools, and complete tasks across various applications.
This is precisely the focal point of Version 3.0: the security risks associated with intelligent agents. The document even incorporates a dedicated intelligent agent risk management framework in its appendix. The question has evolved from 'Is what it says correct?' to 'Is what it does correct?'

The Most Significant Change in 3.0: Risks Extending Beyond the Screen
In my opinion, the most pivotal statement in this document is the recognition that behaviors in virtual space can now spill over and impact the physical world.
Historically, the internet served as a platform for projecting real-world information online; now, the trend has reversed: actions taken by intelligent agents online can directly alter reality.
Consequently, Version 3.0 introduces a structural adjustment by separately outlining risks associated with intelligent agents and embodied AI.
Professor Zhang Linghan succinctly encapsulates this shift: governance has transitioned from ensuring 'large models do not say the wrong thing' in the digital realm to ensuring 'intelligent agents do not do the wrong thing' in the physical world, extending the boundary from content security to behavioral and system security.
Specifically, the newly added risk points are highly targeted. Examples include unintended autonomous behaviors—where AI acts independently without prompting—data poisoning, synthetic data defects, and even a dedicated section on 'threats of autonomous cyberattacks'.
Another entirely new category is 'impacts on cybersecurity risks,' enumerating four types such as the proliferation of cyberattack capabilities, autonomous cyberattacks, and challenges in traceability and accountability.
The corresponding technical measures are equally intriguing: requiring the installation of cybersecurity safeguards, identifying attack intentions, and initiating service degradation, differentially reducing model capabilities, or even refusing to respond upon detecting a user's intent to attack. This is akin to equipping AI with a self-restraining mechanism that activates when malicious intent is detected.
The Goal: Achieving a Dynamic Balance of 'Running Alongside'
Many express concern upon encountering the term 'governance framework': Is this another attempt to stifle innovation?
This document clarifies its stance. It is not a mandatory law but rather a benchmark—regulators utilize it to assess, and enterprises voluntarily align with it, thereby earning user trust in the market.
Regarding governance methods, Version 3.0 emphasizes sandbox supervision and dynamic balance. A sandbox provides a risk-controllable testing ground for new technologies, allowing for mistakes and trial-and-error; dynamic balance means not adhering to a fixed level of strictness but rather tightening regulations when risks are high and loosening them when risks are low.
I particularly appreciate a term used in the document: 'running alongside'—regulation does not stand at the finish line to obstruct but runs alongside, correcting course as needed.
Simultaneously, it does not shy away from the topic of open source. Version 3.0 specifically underscores the security of the open-source ecosystem, requiring clear 'prohibited behaviors' for downloading and using open-source models, drawing red lines while encouraging openness and transparency. Behind this lies a clear understanding: the more powerful AI becomes, the less it can remain a black box, but openness does not equate to laxity.
My assessment is that the true significance of Framework 3.0 lies in its acknowledgment of an ongoing reality: when AI can act autonomously and enter the physical world, the object of security governance must evolve from 'content' to 'behavior'. If this step is not taken proactively, the risks will be significantly greater when intelligent agents widely replace humans in tasks.
Technology advances swiftly, and rules must keep pace without obstructing progress. This 'small steps, running alongside' approach to Chinese-style governance remains to be tested against AI's evolutionary pace, but at least the direction is correct—allowing AI to act, but ensuring it acts correctly.